Skip to content
Notis

Add IP checks to Slack alert triage

A Slack alert can trigger a quick source IP check, giving your team another clue without adding a manual lookup step.

Trigger

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

Action

Check Proxy Status of an IP

Tool to check if an IP address is a proxy. Use after obtaining an IP to detect proxy, VPN, or Tor status.

Why this helps

Alert triage competes with interruptions, making small investigation steps easy to miss.

  • Add IP classification to the existing alert workflow.
  • Reduce context switching during incident triage.
  • Give responders another data point to consider.

Setup

Build it in a few focused steps.

  • 1Connect Slack and Ip2proxy to Notis once.
  • 2Create an automation in the portal or ask Notis to create it conversationally.
  • 3Describe that Notis should check source IPs in Slack alert messages and report proxy, VPN, or Tor status.
  • 4Select the Slack channel message trigger, choose a run-report channel, and test with one real alert IP.

Questions about this workflow

Will it trigger for every alert in a channel?

The channel message trigger runs when a message is posted. The instruction should tell Notis to check source IPs when they are present.

Does the result confirm an incident?

No. It provides an IP classification that responders can consider alongside other evidence.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Slack to Ip2proxy. A trigger fires from one place; an action lands in another.

Slack triggers

Ip2proxy actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Check Proxy Status of an IP

Tool to check if an IP address is a proxy. Use after obtaining an IP to detect proxy, VPN, or Tor status.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

New Channel Created Trigger

Triggered when a new channel is created in Slack.

TriggerInstant

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

TriggerInstant

Direct Message Received

Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.

TriggerInstant

Message Reaction Added

Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Message Reaction Removed

Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Reaction Added Trigger

DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.

TriggerInstant

Connect any two apps with Notis in the middle.

Slack and Ip2proxy, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ip2proxy.